Browsing All Posts filed under »Legal«

When Compliance Forgets Its Purpose

August 2, 2026

0

There is an old saying that bureaucracy expands to consume the time available for its administration. Increasingly that feels less like satire and more like a business model. No sensible executive disputes the need for Know Your Customer (KYC) or Anti-Money Laundering (AML) checks and or controls. They are essential safeguards against fraud, organised crime […]

The Great AI Labelling Illusion; When Compliance Becomes More Important Than Trust

August 1, 2026

0

News is abound that from 2 August, organisations across Europe will proudly inform us that we’re chatting to AI. Websites will politely disclose that the smiling customer service agent is, in fact, a large language model, and marketing images will carry reassuring labels declaring they were generated by artificial intelligence. Progress? Certainly. Protection? That’s another […]

Is Executive Identity The Enterprise Asset Cybersecurity Forgot?

July 18, 2026

0

A rather novel line in a recent policy review leapt out at me. It mandated that users of corporate mobile devices DID NOT customise their voicemail welcome message but leave the default carrier welcome. Why? The creative nature of threat actors are harvesting these custom voice clips to use in AI deepfake autodial human engineering […]

Digital Sovereignty’s AI Conundrum – Who Conditions the Intelligence?

July 5, 2026

0

A follow on thought stimulated by my missive of yesterday on America’s AI Doctrine has me considering the connection and implications on digital sovereignty. For organisations concerned with digital sovereignty, I feel the most challenging growing question is no longer simply one of residency, control or jurisdiction. It is who conditions the intelligence that thinks, […]

America’s AI Doctrine – Move Fast, Until the Pentagon Notices

July 4, 2026

0

Following recent announcements from the US government, the US approach to AI is beginning to resemble a constitutional magic trick. Domestically, Washington wants to sweep away onerous state level safeguards in the name of innovation and competative advantage. The message to Silicon Valley is reassuringly simple; build, scale, dominate and try not to let individual […]

AI’s Tightrope Walk, When Capability Starts to Look Like a Weapon

June 15, 2026

0

Further to my blog at the weekend on the compound systemic risk from an AI runaway event, something further to consider following initial comments I have received, concerns the threshold for offensive use classes of AI falling under Article 36, Additional Protocol-1 and Weapons Review of Lethal Autonomous Weapons System . Noting also that whilst […]

Full Visibility, Zero Control – How Crypto Exposes the Illusion of Financial Power

May 15, 2026

0

There was a time when Bitcoin was dismissed as the preserve of hoodie wearing anarchists and fringe actors and was misunderstood to be empowering the individual with financial anonymity. Today, it is monitored with such analytical precision that one could almost imagine His Majesties revenue & Customs (HMRC) preferring to audit the ledger itself rather […]

Duty of Care in a Post-Mythos World, When Continuous Evidence Replaces Static Assumption

April 22, 2026

0

Further to my earlier post following the arrival of Mythos class AI capable of surfacing vulnerabilities and weaponising them by chaining them at machine speed. I would like to explore further and more explicitly how this has reset the baseline for organisational accountability and risk, whether this is acknowledged yet by some is only a […]

Mythos and the Cyber Event Horizon, When Visibility Outpaces Control

April 17, 2026

0

It feels a bit like we have crossed a cyber event horizon with the release of Anthropic’s latest Mythos AI, an LLM optimised for vulnerability detection. Much of the noise centres on whether it enables better hacking at machine speed, which I believe is a bit of a distraction from the practical impact. The more […]

What is The Most Dangerous Layer in AI, Where Trust Is Won or Lost?

April 13, 2026

0

The AI conversation has been dominated by model size, training breakthroughs and eye-watering infrastructure spend but I get a real sense that this is increasingly the wrong lens. For me the true battleground is not where AI is built, it is where it is used and that place is inference. Inference is where AI models […]

Are You Defending the Right Battlefield?

April 11, 2026

0

For most organisations and even those in the Cyber security industry itself, they still imagine their digital adversary as a system intruder. Firewalls are hardened, endpoints instrumented, identities wrapped in layers of conditional access and on and on … Yet the majority of losses are not coming from breached systems, they are flowing through human […]

AI in Audit and the Fragility of Trust

April 3, 2026

0

As EY showcases its AI audit platform ‘Canvas’ in the Big 4 AI arms race, the UK’s Financial Reporting Council (FRC) has barely had time to publish its first guidance on generative and agentic AI. I see a familiar tension emerging, innovation is accelerating faster than the mechanisms designed to trust it. As I have […]

When Cyber War Targets Healthcare – The Moral Collapse Behind Iran’s Digital Proxies

March 29, 2026

0

As an extended thought exercise from my earlier piece on the digital risk from smart city infrastructure in kinetic warfare scenarios, Iran’s expanding use of cyber operations against such civilian infrastructure represents not merely validation of that hypothesis or even just an escalation in conflict but I believe also a profound erosion of moral boundaries […]

Sovereign AI and the Cyber Risk of the Well-Governed Target

March 12, 2026

0

Are we building sovereign AI infrastructure that is legally controlled but operationally fragile? The current conversation around sovereign AI is dominated by a sensible instinct, keep the models, data and compute that underpin critical national capability within national jurisdiction. Governments want AI infrastructure they control, regulate and can trust. Nice and tidy for the pen […]

Reducing Risk in High-Pressure Cybersecurity Environments

March 8, 2026

0

As an avid fitness enthusiast, the modern ability to access personal metabolic and activity data has fascinated me ever since I first began exploring it more than 25 years ago. Anyone else remember the bulky Garmin Forerunner 101? How things have changed since then. With nearly half a lifetime of training data, now enriched by […]